CISA Flags Four Actively Exploited Vulnerabilities Across SonicWall and Microsoft Products
CISA's addition of four vulnerabilities to its Known Exploited Vulnerabilities Catalog — spanning SonicWall SMA1000 appliances, Microsoft Active Directory Federation Services, and SharePoint Server — signals that threat actors are actively weaponizing these flaws in the wild. The presence of identity and federation infrastructure (ADFS) and widely-used collaboration platforms (SharePoint) among the affected products significantly raises the stakes, as exploitation can lead to credential theft, lateral movement, and full domain compromise. Organizations that delay patching public-facing assets create windows of opportunity that adversaries are demonstrably exploiting. CISA's Binding Operational Directive (BOD) 26-04 underscores that for federal agencies — and by extension, any organization with critical infrastructure — timely remediation of KEV-listed vulnerabilities is not optional.
Tactical Insight
Immediate actions
- Apply vendor-released patches for SonicWall SMA1000, Microsoft ADFS, and SharePoint Server without delay, prioritizing internet-facing instances.
- Cross-reference your asset inventory against the CISA KEV Catalog and flag any unpatched systems for emergency remediation.
Long-term improvements
- Establish a formal emergency patching SLA (e.g., 24–72 hours) specifically for vulnerabilities listed in the CISA KEV Catalog.
- Maintain a continuously updated and accurate inventory of all public-facing assets, including network appliances and identity providers.
- Implement network segmentation to isolate identity infrastructure (e.g., ADFS) and remote access appliances from the broader internal network.
Detection measures
- Deploy vulnerability scanning tools configured to alert on KEV-listed CVEs as soon as they are published.
- Monitor authentication logs on ADFS and SharePoint for anomalous access patterns that may indicate active exploitation attempts.